Establishing secure connection…Loading editor…Preparing document…

Cybersecurity Pentest Proposal

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

CYBERSECURITY PENETRATION TEST PROPOSAL

Parties and Proposal Date

Client Name:

Service Provider Name:

Proposal Effective Date:

Recitals

WHEREAS, Client engages Service Provider to conduct cybersecurity testing and related professional services as set forth in this Proposal; and

WHEREAS, Service Provider represents that it possesses the technical expertise, certification, tools and personnel necessary to perform penetration testing in accordance with industry standards and agreed scope; and

WHEREAS, the parties desire to set forth the scope, deliverables, schedule, fees and legal terms applicable to the engagement.

Scope of Work

Description of services to be performed. Service Provider shall perform a penetration test limited to the components and test types selected below, executed in a manner to minimize disruption to Client operations. The engagement shall include vulnerability discovery, exploitation where authorized, post-exploitation analysis, and remediation validation as set forth in this Proposal.

Testing Methodology & Deliverables

Service Provider will apply recognized testing methodologies, including active reconnaissance, authenticated and unauthenticated scanning, controlled exploitation, privilege escalation and post-exploitation analysis where authorized. Testing will conform to agreed time windows, rules of engagement and safe testing practices.

Network Infrastructure Web Application Mobile Application

Cloud Configuration Social Engineering (phishing)

Assumptions and Exclusions

Payment Terms

Total Fee:

Invoice Due Within (days):

Late Fee:

Term and Termination

Engagement Start Date:

Engagement End Date:

Either party may terminate this engagement for material breach if the breaching party fails to cure such breach within the notice period specified above, except that Client may terminate for convenience upon payment of all fees for work performed through the termination date.

Confidentiality

Each party shall maintain in strict confidence all Confidential Information disclosed by the other party in connection with this engagement. Confidential Information includes test results, exploitation details, evidence of vulnerabilities, remediation guidance, and any assessment reports. Confidential Information shall not be disclosed to any third party without the disclosing party's prior written consent except as required by law or to permitted contractors who are bound by equivalent confidentiality obligations.

Service Provider shall not publish or disclose any exploit details, proof-of-concept code, or raw evidence that would enable an exploit without Client's prior written consent. All deliverables marked as Confidential shall remain the sole property of Client for purposes of confidentiality.

Limitation of Liability & Indemnification

To the maximum extent permitted by law, the aggregate liability of Service Provider for claims arising out of this engagement shall not exceed the total fees actually paid by Client for the services provided under this Proposal. Neither party shall be liable for special, incidental, consequential or punitive damages, including loss of business or profits, even if advised of the possibility of such damages.

Client shall indemnify and hold harmless Service Provider from claims arising from Client's failure to obtain necessary permissions, from Client-supplied materials that introduce vulnerabilities, or from any misuse of deliverables by Client or third parties, except to the extent caused by Service Provider's willful misconduct or gross negligence.

Client Responsibilities

Change Orders

Any changes to scope, schedule or fees shall be documented in a written change order signed by authorized representatives of both parties. Change orders may adjust price, timeline and deliverables as necessary.

Governing Law

This Proposal and any resulting agreement shall be governed by and construed in accordance with the laws of the jurisdiction specified below, without regard to conflict of law principles.

Entire Agreement

This Proposal, together with any executed change orders or exhibits expressly incorporated herein, constitutes the entire agreement between the parties with respect to the subject matter and supersedes all prior discussions, proposals and agreements, whether written or oral. Any modifications must be in writing and signed by authorized representatives of both parties.

Acceptance

By signing below, the parties acknowledge that they have read, understand and agree to be bound by the terms of this Proposal and authorize Service Provider to proceed with the work described herein upon receipt of any required deposits.

Client Printed Name:

By:

Date:

Service Provider Printed Name:

By:

Date:

Enter text✕

What a Cybersecurity Pentest Proposal Is

A Cybersecurity Pentest Proposal is a formal, written offer from a penetration testing provider that describes the planned security assessment for a client. It identifies scope, objectives, test methods, schedule, deliverables, liability limits, and pricing so both parties understand responsibilities and outcomes before any testing begins. The document frames technical details and legal terms that govern controlled testing against systems, applications, networks, and environments to reduce operational risk while preserving evidence and privacy.

Why a Clear Proposal Matters for Risk and Compliance

A concise proposal reduces ambiguity, aligns expectations, and documents consent for controlled security testing. It helps avoid accidental service disruptions, demonstrates due diligence for audits, and records contractual limits that affect liability and remediation responsibilities.

Why a Clear Proposal Matters for Risk and Compliance

Who Typically Prepares and Reviews Pentest Proposals

Organizations preparing for a penetration test often involve technical, legal, and procurement stakeholders to ensure the engagement is safe, compliant, and contractually sound.

  • In-house security teams and CISOs who define technical objectives and accept risk trade-offs.
  • Procurement and vendor management teams who review pricing, terms, and SLAs.
  • Legal, compliance, and privacy officers who confirm contractual protections and regulatory consistency.

A multidisciplinary review helps prevent scope creep, ensures proper authorization, and documents approvals required for safe execution.

Essential Sections to Include in Every Pentest Proposal

A professional Pentest Proposal groups technical scope, schedule, rules of engagement, deliverables, pricing, and legal terms. Each section should be clear enough for legal review while detailed enough for technical planning.

Scope definition

Targets, exclusions, test types (external, internal, web, mobile), and success criteria.

Rules of engagement

Authorized IPs, testing hours, acceptable testing methods, and escalation contacts.

Schedule and milestones

Start/end dates, interim checkpoints, and remediation windows.

Deliverables

Interim findings, final report format, repeatable evidence, and retest options.

Pricing and payment

Fixed-fee or time-and-materials, change-order terms, and invoicing cadence.

Legal and liability

Indemnities, confidentiality, data handling, limitations of liability, and insurance.

Step-by-Step: Preparing a Complete Pentest Proposal

Follow this sequence to draft, review, and finalize a secure and enforceable proposal that aligns technical work with legal protections.

  • 01
    Draft scope: Define targets, exclusions, and testing methods in plain language.
  • 02
    Estimate cost: Choose fixed or hourly pricing and note change-order triggers.
  • 03
    Legal review: Confirm indemnities, confidentiality, and data handling with counsel.
  • 04
    Obtain signoff: Collect authorized signatures and record the execution date.

Customizing the Proposal in an Online Workflow

Configure an online template to enforce required fields, conditional sections, and approver routing for faster, auditable execution.

Field Configuration
Scope field Mandatory multiline textarea with attachment option
Test window Date picker with MM/DD/YYYY validation
Approvals Conditional routing to legal and security reviewers
Signatures Role-based signature fields with date stamps

Where to Send the Proposal and How It’s Processed

Determine recipient roles and routing to make acceptance clear and to ensure that authorized parties approve testing in writing.

  • Send to procurement: Procurement validates pricing and payment terms.
  • Route to legal: Legal confirms liability, confidentiality, and data clauses.
  • Notify security team: Security schedules testing and coordinates maintenance windows.
  • Archive executed copy: Store the signed proposal with audit trail for compliance.

Digital Signing and Distribution Requirements

Use a platform that preserves an audit trail, supports required file formats, and integrates with your document systems.

  • File formats: PDF, DOCX, HTML, Excel supported.
  • Integrations: Salesforce, Microsoft 365, NetSuite, Google Workspace.
  • Authentication: Email, SMS, or advanced signer verification.

Ensure the chosen solution can export a tamper-evident signed file and store metadata such as timestamps, IP addresses, and signer identity.

Core Security and Operational Data to Include

Scope details: Targets and exclusions
Test timeframe: Start and end dates
Asset inventory: IP addresses and hostnames
Access methods: Credentials and VPN details
Data handling: Sensitive data restrictions
Liability limits: Caps and insurance

Common Preparation Mistakes to Avoid

  • Unclear scope that leads to unauthorized testing
  • Missing escalation contacts during incidents
  • Failure to record authorized IPs or assets
  • Insufficient legal review of indemnities and data handling

Key Legal and Operational Risks

Contract unenforceability: Ambiguous terms may void protections
Data exposure: Inadequate controls risk PHI/PII leaks
Regulatory breach: Noncompliance with HIPAA or FERPA
Insurance denial: Coverage may be refused for excluded risks
Civil liability: Third-party claims for damages
Operational outage: Testing may disrupt production services

Typical Timing and Deadlines in a Proposal

Set clear dates and response deadlines to prevent misunderstandings and to trigger scheduling and notification processes.

Proposal issue date:

Date the provider delivers the proposal to the client.

Acceptance deadline:

Timeframe for client signature and authorization (commonly 7–21 days).

Test window:

Authorized period for active testing and agreed time blocks.

Remediation window:

Period for client fixes before retest is scheduled.

Final report delivery:

Delivery date for the assessment report after testing completes.

Key Milestones from Proposal to Final Report

Track sequential milestones so responsibilities and timing are evident for both parties during the engagement.

01

Proposal Issued

Provider sends proposal and terms for review.

02

Contract Signed

Authorized signatories accept scope and legal terms.

03

Testing Performed

Active penetration testing within agreed window.

04

Final Report Delivered

Provider issues findings, evidence, and remediation recommendations.

Real-World Examples of Signed Security Proposals

Two examples show how organizations document scope, approvals, and outcomes when engaging external testers.

Optica Ventures — COO

Optica documented a phased external test to avoid operational impact.

  • Phased testing limited blast radius.
  • The approach made approvals straightforward and allowed targeted remediation based on clear, timely reports and controlled evidence handling.

Xerox — Director of NetSuite Operations

Xerox integrated proposal approvals with NetSuite workflows for procurement.

  • Integration automated signatures and storage.
  • Using integrated approvals improved traceability across departments and ensured the signed proposal and audit trail were available where operations and finance expected them to be stored.

Best Practices for Drafting Clear and Enforceable Proposals

Follow these practices to reduce legal ambiguity, improve operational safety, and simplify post-test remediation and reporting.

Describe scope with precision
Use explicit lists of IPs, hostnames, and application endpoints. Avoid general phrases like 'all company assets' and instead enumerate systems and environments to prevent unauthorized testing and to clarify responsibility for outages.
Define acceptable methods and tools
Specify prohibited activities such as denial-of-service testing or social engineering if not authorized. Listing allowed techniques and excluded methods prevents misunderstandings and reduces legal exposure if a test unintentionally affects availability.
Include incident escalation procedures
Provide a clear 24/7 contact for emergency pauses and include expected response times. A documented escalation path minimizes operational risk and supports rapid remediation if a test triggers a service-impacting issue.
Record evidence and retest terms
State how evidence will be collected, redacted, and stored, and define conditions for retest after fixes. This clarifies expectations for verification and protects both parties during remediation cycles.

How a Pentest Proposal Differs from a Vulnerability Assessment

Use this comparison to determine whether you need an active penetration test or a lower-impact vulnerability scan and to shape proposal language accordingly.

Criteria Pentest Proposal Vulnerability Assessment
Interaction level active exploitation passive scanning
Scope depth deep, exploit-focused broad, discovery-focused
Operational risk higher lower
Typical deliverable exploit evidence and risk narrative findings list and severity

eSignature Vendor Pricing and Feature Comparison

Compare basic pricing and feature availability for common eSignature providers used to execute proposals and capture legally binding signatures.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day free trial No No Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently Asked Questions and Practical Answers

Answers to common legal, technical, and process questions encountered when preparing or executing a Pentest Proposal.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users